Privacy Policy

Version 1.0 — Effective date: June 15, 2026
Operated by: DIGITAL SPECTRUM S.R.L.
Contact: privacy@eupostez.md


1. Introduction

This Privacy Policy explains how DIGITAL SPECTRUM S.R.L. (“we”, “us”, “our”) collects, uses, stores, and protects personal data when you use the Eu Postez platform at eupostez.md (“the Platform”). It applies to all visitors, registered users, and anyone whose content is processed through a connected social media account.

We operate under the General Data Protection Regulation (EU) 2016/679 (GDPR) and the data protection laws of the Republic of Moldova (Law No. 133 of 08.07.2011 on Personal Data Protection).

Questions? Email privacy@eupostez.md before using the Platform.


2. Data Controller

DIGITAL SPECTRUM S.R.L.
Calea Iesilor 6A, Office A304
Chisinau, Republic of Moldova
Email: privacy@eupostez.md
Website: https://eupostez.md


3. What Data We Collect

3.1 Account and Registration Data
When you create an account:

  • Full name
  • Email address
  • Business or brand name
  • Country
  • Password (stored as a cryptographic hash — never readable)
  • Two-factor authentication credentials (if enabled)

3.2 Brand Profile Data
To allow LaraAI to generate content on your behalf, you provide:

  • Industry and business description
  • Target audience information
  • Brand voice and tone preferences
  • Content topics and preferred calls to action
  • Words and phrases to avoid

This data is used exclusively to personalise LaraAI-generated captions for your account.

3.3 Social Media Account Credentials
When you connect a social media account, we receive and store:

  • An OAuth access token issued by the social media platform
  • A refresh token (where provided)
  • Your platform-specific user ID and display name
  • Your profile picture URL (for display only)

We never receive or store your social media password. All tokens are encrypted using AES-256-GCM before storage.

3.4 Content Data

  • Source text, ideas, or briefs you enter
  • Images and video files you upload (stored temporarily for processing)
  • LaraAI-generated captions and hashtags
  • Published captions once sent to social media platforms

3.5 Usage and Technical Data

  • IP address and approximate location (city/country)
  • Browser type and operating system
  • Login timestamps and session identifiers
  • Features used and actions taken within the Platform
  • Error logs

3.6 Payment Data
Payments are processed by Stripe, Inc. We receive only: last four digits of your card, card type, expiry date, billing country, and Stripe customer identifiers. We never store full card numbers or CVV codes.

3.7 Communications
If you contact us by email or through the Platform, we retain the content of that message and our response.


4. Legal Basis for Processing (GDPR Art. 6)

Purpose Legal Basis
Creating and managing your account Performance of contract — Art. 6(1)(b)
Generating LaraAI captions from your brand profile Performance of contract — Art. 6(1)(b)
Publishing content to connected social accounts Performance of contract — Art. 6(1)(b)
Processing payments Performance of contract — Art. 6(1)(b)
Transactional emails (alerts, billing) Performance of contract — Art. 6(1)(b)
Fraud prevention and platform security Legitimate interests — Art. 6(1)(f)
Product updates and feature announcements Legitimate interests — Art. 6(1)(f) (opt-out available)
Legal obligations Legal obligation — Art. 6(1)(c)

5. How LaraAI Processes Your Content

Eu Postez uses LaraAI, our AI assistant powered by the Claude API (Anthropic, PBC), to generate captions and content suggestions. When you request AI-generated content:

  • Your source text, brand profile, and platform preferences are sent to Anthropic’s API
  • Anthropic processes this data and returns a response to our servers
  • Anthropic’s API usage policy prohibits using API inputs to train their models
  • No personal data beyond what is necessary to generate the caption is transmitted

Anthropic’s privacy policy: anthropic.com/privacy


6. Social Platform Data and Permissions

When you connect a social media account, we request only the permissions necessary to publish the content you upload and approve. We do not access your followers, private messages, or any data beyond what is required to operate the Platform.

Meta (Facebook and Instagram)
Permissions requested: pages_show_list, pages_read_engagement, pages_manage_posts, business_management, instagram_business_basic, instagram_business_content_publish.
Purpose: to publish content you have reviewed and approved to your Facebook Pages and Instagram accounts.

TikTok
Permissions requested: user.info.basic, video.upload, video.publish.
Purpose: to upload and publish videos you have reviewed and approved.

LinkedIn
Permissions requested: openid, profile, email, w_member_social, r_organization_social, w_organization_social.
Purpose: to publish posts you have reviewed and approved to your profile and company pages.


7. Data Retention

Data Type Retention Period
Account data Duration of account + 30 days after deletion
Social media OAuth tokens Deleted immediately on disconnect or account deletion
Post content and captions 90 days after deletion or account closure
Uploaded media (images/video) Deleted within 72 hours of processing
Usage and security logs 12 months
Payment and invoicing records 7 years (legal requirement)
Waitlist form submissions Until account created, or 24 months if no account

8. Third Parties and Data Sharing

We share personal data only to the extent necessary to deliver the Platform:

Third Party Purpose Location
Anthropic, PBC LaraAI caption generation United States
Stripe, Inc. Payment processing United States
Hetzner Online GmbH Server hosting and infrastructure Germany (EU)
Meta Platforms, Inc. Publishing to Facebook and Instagram United States
TikTok Ltd. Publishing to TikTok Singapore / United States
LinkedIn Corporation Publishing to LinkedIn United States

For transfers outside the EU/EEA we rely on Standard Contractual Clauses (SCCs) approved by the European Commission or equivalent transfer mechanisms.

We do not sell, rent, or share your personal data with advertisers, data brokers, or any third party for their own commercial purposes.


9. Your Rights

Under GDPR and applicable Moldovan law you have the right to:

  • Access — request a copy of the personal data we hold about you
  • Rectification — correct inaccurate or incomplete data
  • Erasure — request permanent deletion of your data (see Section 10)
  • Restriction — ask us to pause processing in certain circumstances
  • Portability — receive your data in a machine-readable format
  • Object — object to processing based on legitimate interests
  • Withdraw consent — where processing is based on consent, withdraw it at any time

To exercise any right, email privacy@eupostez.md. We will respond within 30 days and may ask you to verify your identity.

To lodge a complaint:
National Centre for Personal Data Protection of the Republic of Moldova
Website: https://www.dataprivacy.md

EU residents may also contact their local supervisory authority.


10. Data Deletion

You may delete your account at any time in Settings → Security → Delete Account. All personal data is permanently deleted within 30 days. For full instructions see our Data Deletion page at eupostez.md/data-deletion.


11. Security

  • All data in transit encrypted via TLS 1.2 or higher
  • All data at rest encrypted via AES-256
  • OAuth tokens encrypted with per-account cryptographic keys
  • Passwords stored as bcrypt hashes — never readable
  • Two-factor authentication available on all accounts
  • Production access restricted to authorised personnel only
  • We will notify you within 72 hours of any breach affecting your data (GDPR Art. 33)

12. Cookies

We use only strictly necessary cookies, plus functional browser storage to remember your preferences (such as language and layout). We do not use advertising, tracking, or analytics cookies. For full details see our Cookie Policy at eupostez.md/cookie-policy.


13. Children’s Privacy

The Platform is not directed at individuals under 18. We do not knowingly collect data from minors. Contact privacy@eupostez.md if you believe a minor has provided us with data.


14. Changes to This Policy

We will notify registered users by email at least 14 days before any material change takes effect. The effective date at the top of this page always reflects the current version.


15. Contact

DIGITAL SPECTRUM S.R.L.
Calea Iesilor 6A, Office A304, Chisinau, Republic of Moldova
privacy@eupostez.md · https://eupostez.md